Incident Response and Reporting Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Incident Response and Reporting flashcards as text
Which incident response phase involves restoring affected systems to normal operations and verifying they are fully functional?
Answer: Recovery
The Recovery phase involves restoring systems from clean backups or rebuilding them, then monitoring to confirm normal operations before returning to full production.
A cybersecurity insurance carrier requires notification of a covered incident within 24 hours of discovery. Failing to meet this requirement may result in:
Answer: Denial or reduction of the insurance claim
Cyber insurance policies typically include strict notification clauses; late reporting can void coverage or reduce claim payouts.
Which of the following best describes the role of a 'Computer Security Incident Response Team' (CSIRT)?
Answer: A dedicated group that coordinates the detection, analysis, and response to cybersecurity incidents
A CSIRT is an organizational team responsible for receiving, reviewing, and responding to cybersecurity incident reports and activities.
Under the SEC cybersecurity disclosure rules effective 2023, publicly traded companies must report material cybersecurity incidents on Form 8-K within:
Answer: 4 business days of determining materiality
The SEC's 2023 cybersecurity rules require registrants to disclose material cybersecurity incidents on Form 8-K within four business days of determining the incident is material.
Which technique involves an attacker maintaining persistent access after initial compromise by installing backdoors — a behavior that incident responders must identify during which phase?
Answer: Eradication
During eradication, responders must identify and remove all backdoors and persistence mechanisms to ensure the attacker cannot regain access after recovery.
A healthcare organization experiences a ransomware attack affecting 400 patient records. Under HIPAA, media notification is required when the breach affects more than:
Answer: 500 individuals in a state or jurisdiction
HIPAA requires covered entities to notify prominent local media outlets when a breach affects more than 500 individuals in a state or jurisdiction.
Which tool or artifact would provide the MOST reliable evidence of the exact commands executed by an attacker on a compromised Linux server?
Answer: Bash history file and auditd logs
The bash history file and Linux auditd logs record executed commands and system calls, providing detailed evidence of attacker activity on a compromised host.